Data & Document Retention
What we retain, who may see it, when it is deleted and which business records must remain available under law.
Policy version 15 September 2026Scope
This policy covers account data, dealer applications, business and identity documents, store photographs, communications, buyer-ID administration, bids, orders, payment evidence, invoices, shipment records, security logs and backups handled through the Japan Brand Auction service.
Where information is kept
Application data is held in the service’s access-controlled cloud database. Private supporting files are held in non-public object storage and are delivered only after an authorised request. Public catalogue photographs are stored and served separately from applicant documents.
Our internal provider register records each material hosting, authentication, payment and communication provider, its processing location, applicable safeguards and deletion mechanism. The register is reviewed whenever a provider or processing route changes.
Who may access it
Applicants can access their own eligible records. Internal access is limited to NG KAMWAI and specifically authorised review, operations or system administrators who require access for application review, transaction support, security or legal compliance. Access must not be granted merely because a person has general administrative status.
Service providers receive only the data needed for their function. Access and material administrative activity should be logged and reviewed.
Retention schedule
| Record | Current retention rule |
|---|---|
| Declined, withdrawn or abandoned application and supporting documents | Delete three months after the review or withdrawal is completed, unless a dispute, fraud investigation or legal duty requires a temporary hold. |
| Approved dealer application, identity and business verification documents | Keep during the dealer relationship; delete three months after the relationship ends, subject to a documented legal hold. |
| Account profile and ordinary application correspondence | Keep while the account or review is active; delete or anonymise three months after the relationship or review ends unless needed for a continuing transaction. |
| Contracts, accepted order terms, invoices, receipts and tax-relevant transaction records | Keep for the period required by Japanese law, generally at least seven years for relevant corporate tax records and longer where a specific rule applies. |
| Payment, order, shipment, customs and dispute records | Keep for the applicable statutory period and while a claim, chargeback, audit or dispute remains open. |
| Security and administrative audit records | Keep only as long as proportionate for security, investigation and accountability under the documented internal retention schedule. |
| Independent document backups | No independent document backup is currently active. Before one is introduced, its encryption, access, retention, deletion and restore-test rules will be documented and this policy will be updated. |
Deletion and legal holds
Deletion means removal from active systems or irreversible anonymisation where appropriate. If an independent backup is introduced later, its expiry process will be added to this policy before use. Before deleting a dealer record, COCO must separate application and identity documents from contracts, invoices and transaction records that remain legally required.
A deletion schedule may be paused for an unresolved payment, delivery, dispute, suspected fraud, regulatory request or litigation hold. The reason, scope and review date should be recorded; a hold must not become indefinite by default.
Operational controls
- Assign an owner for each record category and review overdue records on a fixed schedule.
- Use role-based access, strong authentication and prompt access removal when duties change.
- Keep private documents out of public links, email attachments and product-media storage.
- Record exports, administrative access, review decisions and deletions where technically appropriate.
- Test restoration and deletion procedures and document any security incident.
Requests
To request access, correction or deletion, email mingyang851@gmail.com (小嗚) or lucky79@gmail.com (Mia). We will verify the requester, explain any lawful reason for retaining a record, and confirm the action taken where required.